Renew Certificate

Handian Sudianto 7,461 Reputation points
2026-09-07T13:10:23.72+00:00

I push dot1x certificate from intune and the certificate itself generated by our internal microsoft ca server. If the certificate will be expired on 2 months then how we can renew the certificate to make sure the dot1.x is not interuppted.

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
0 comments No comments

1 answer

Sort by: Most helpful
  1. Domic Vo 32,305 Reputation points Independent Advisor
    2026-09-07T13:54:58.7166667+00:00

    Hello Handian,

    For Intune-delivered 802.1X certificates that are issued from your internal Microsoft CA, renewal is handled through the SCEP or PKCS certificate profile you configured in Intune. As long as the profile is still assigned and valid, Intune will automatically request a new certificate from the CA before the current one expires. The renewal window is controlled by the CA template configuration. By default, Windows clients attempt renewal when 80% of the certificate lifetime has passed. For example, if the certificate validity is one year, renewal will start around the 9-10 month mark.

    To ensure smooth renewal, you should verify two things. First, check the certificate template on your CA under Certification Authority > Certificate Templates. Confirm that “Renewal period” is set appropriately (for example, 2 months before expiration). Second, make sure the Intune profile is still active and assigned to the devices. If the template allows renewal and Intune continues to push the profile, the client will automatically request a new certificate from the CA without user intervention.

    If you want to force a renewal earlier, you can manually delete the existing certificate from the user’s personal store (certmgr.msc > Personal > Certificates) and then trigger a sync from Intune (Settings > Accounts > Access work or school > Sync). The device will then request a fresh certificate from the CA via Intune.

    In short, you don’t need to manually reissue certificates if the template and Intune profile are correctly configured. Just ensure the renewal period in the CA template is set to cover your 2‑month window, and Intune will handle the rest.

    I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!

    DV.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.